CVE-2002-0371 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 54.4% (pctl 99)
Patch early
A public exploit exists.
Description
Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 54.44% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-07-03 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| microsoft | internet explorer |
| microsoft | isa server |
| microsoft | proxy server |
| university of minnesota | gopher |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Internet Explorer 5/6 / Microsoft ISA Server 2000 / Microsoft Proxy Server 2.0 Gopher Client - Remote Buffer Overflow | 2002-07-27 |
References
- http://marc.info/?l=bugtraq&m=102320516707940&w=2
- http://marc.info/?l=bugtraq&m=102397955217618&w=2
- http://online.securityfocus.com/archive/1/276848
- http://www.iss.net/security_center/static/9247.php
- http://www.kb.cert.org/vuls/id/440275
- http://www.pivx.com/workaround_fail.html
- http://www.securityfocus.com/bid/4930
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-027
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A98
- http://marc.info/?l=bugtraq&m=102320516707940&w=2
- http://marc.info/?l=bugtraq&m=102397955217618&w=2
- http://online.securityfocus.com/archive/1/276848
- http://www.iss.net/security_center/static/9247.php
- http://www.kb.cert.org/vuls/id/440275
- http://www.pivx.com/workaround_fail.html
- http://www.securityfocus.com/bid/4930
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-027
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A98
→ the Explorer · watch your stack · NVD